Privacy Policy
Last updated: 16 August 2026
Controller
Rasofia Games
The Hague, The Netherlands
Email: contact@enterthezone.app
We are the data controller for the personal data described here. We have not appointed a Data Protection Officer, as we are not required to.
The short version
If you use The Zone without an account, we receive no personal data at all — everything stays in your browser. If you create an account, we store your email address and the focus data you choose to sync. We do not use advertising or analytics trackers, we do not profile you, and we never sell your data.
What we collect
- Account data — your email address and a hashed password. Collected when you sign up.
- Your content — projects, focus blocks, sessions and the reflection notes you write, but only if you are signed in. Signed out, this never leaves your device.
- Entitlement records — whether your account has Premium, and the Paddle transaction id, amount, currency and status of your purchase.
- Technical logs — our hosting and database providers keep short-lived server logs including IP address, for security and abuse prevention.
We do not collect payment card details. Those go directly to Paddle and we never see them.
Why, and on what legal basis
- Providing the Service (accounts, sync, Premium features) — performance of a contract, GDPR art. 6(1)(b).
- Processing your purchase and keeping tax records — contract and legal obligation, art. 6(1)(b) and (c).
- Security, abuse prevention and debugging — legitimate interests, art. 6(1)(f).
- Service emails (password reset, purchase confirmation, material changes) — contract. We do not send marketing email.
Who processes it
- Supabase — database, authentication and serverless functions. Our project is hosted in the EU (eu-west), so your data stays within the European Economic Area.
- Paddle.com Market Ltd (United Kingdom) — Merchant of Record. Paddle is an independent controller for payment and tax data; see the Paddle Privacy Policy. Transfers to the UK rely on the European Commission's UK adequacy decision.
- Hostinger — serves the website files.
Some third-party assets (Google Fonts, Tailwind, and the Supabase and Paddle scripts) are loaded from their providers when you open the app, which means those providers receive your IP address as part of serving the request. We do not send them any other information about you.
How long we keep it
- Account and content — until you delete your account, then removed within 30 days.
- Purchase and tax records — 7 years, as required by Dutch tax law. This survives account deletion.
- Server logs — per our providers' retention, typically days to a few weeks.
Your rights
Under the GDPR you have the right to access, rectify, erase, restrict or object to processing of your personal data, and the right to data portability. To exercise any of these, email contact@enterthezone.app. We will respond within one month.
You can export your own content at any time from Settings. If you believe we have handled your data improperly, you may complain to the Dutch DPA, the Autoriteit Persoonsgegevens, or to the authority in your country of residence.
Cookies and local storage
We use no advertising or analytics cookies, so there is no consent banner. We use browser localStorage to keep your data and settings on your device, and Supabase sets a first-party token to keep you signed in. Both are strictly necessary for the Service to function. Paddle may set its own cookies during checkout; that is covered by Paddle's policy.
Security
Data is encrypted in transit over TLS and at rest by our database provider. Access to your rows is enforced at the database level so one account cannot read another's data. Passwords are stored hashed by Supabase Auth and are never visible to us. No system is perfectly secure; if a breach affects your data we will notify you and the regulator as the GDPR requires.
Changes
We will post updates here and, for material changes, notify you by email.